Opinion: Anthropic's Claude can send Gmail autonomously, while Google blocks Gemini
Anthropic’s August 2026 update lets Claude read incoming Gmail messages, draft replies and forward them, and optionally send them without user confirmation. By default the assistant asks before sending, but users can disable the check, putting the model in a YOLO mode that writes under the user’s name. The feature can handle batch operations, such as generating forty thank‑you emails from a…
What you can do with it
AI at Work →writes and sends Gmail messages automatically
- Who for
- marketers, founders and operations
- Cost
- Cost not stated
- Effort
- minutes
Use it for
- reply to routine inquiries
- send batch thank‑you notes
- confirm calendar meetings
Watch out If Claude hallucinates, sent emails cannot be undone and may expose sensitive information.
Key points from the news
- Claude can read, draft, and send Gmail messages, with an optional YOLO mode that skips user confirmation.
- Google’s Gemini still requires manual send confirmation and does not allow autonomous email dispatch.
- Anthropic’s feature can batch‑write up to 40 emails per prompt, but mis‑sent messages are permanent.
Google’s Gemini, by contrast, still requires a manual press‑send step and does not permit autonomous dispatch. The author argues that Google’s larger user base and billions of daily messages make it risk‑averse, fearing a single model failure could enable large‑scale scams. Anthropic’s smaller, paying‑subscriber audience allows it to be more aggressive, though the risk of hallucinated or maliciously injected content remains, especially since email lacks a reliable undo function.
Claude can send emails without asking; Google still won't let Gemini press send on its own
androidpolice.com · 20 September 2026
Google owns Gmail. Google builds Gemini. And Google still won't let Gemini press send on its own. Well, Anthropic will.
Its August 2026 update to the connector lets Claude read an incoming email, write the reply, and send it to someone else's inbox.
That's a thrilling sentence and a frightening one, depending on what the email says.
Where Claude and Gemini differ in Gmail
Reading your mail is standard; show me more
Let's start where Anthropic's documentation starts. That covers searching your mail, listing saved drafts, summarizing long threads, and reading message metadata.
None of that is new ground, because every assistant reads your mail these days. But keep reading, and you get to the write actions.
Claude can also send, reply to, and forward emails from Gmail. It checks with you first by default. But you can switch that off and let it go YOLO.
At that point, you have an agent writing under your name. Now let's compare permissions with Gemini.
Forty emails from one prompt is great until one of them is wrong
Scale works in both directions
The upside is scale. Batch email has always meant either a mail merge that reads, well, like a mail merge, or an afternoon of copy-and-paste.
An agent that can read context and write 40 messages is impressive.
Give Claude a list of 40 conference attendees and ask it to thank each one for coming, with a line about the session they attended. That's one prompt instead of 40 tabs.
But this cuts both ways. Email has no reliable undo function. After a message leaves your outbox, it's a record that stays in the recipient's inbox permanently and speaks with your authority.
An agent that hallucinates a bad response to a client is a record you now have to explain. Fixing it means writing the embarrassing follow-up, and that one's permanent as well.
My reading is that Google probably can't afford what Anthropic can risk
A smaller blast radius buys room to be aggressive
Google's risk profile is different from Anthropic's. Gmail moves billions of messages a day and handles a constant stream of phishing and malicious payloads.
Give that user base autonomous sending, and one model failure is all it takes for the headline to read "Google's AI helped run a scam."
That's not the only reason. However, it is a fair assumption that nobody at Google fancies defending an unattended agent sending emails at scale.
Anthropic's blast radius is smaller, and its users chose to be there. Claude's audience who can use this are paying subscribers who connected Gmail on purpose.
It's inherently different from a billion people who got an AI button added to an app they already had.
It deploys the feature and hands the liability downstream, which is why a third party can be more aggressive than the platform owner.
What happens when your agent takes orders from a stranger's email?
Guardrails lower the odds and don't remove them
Prompt injection worries me most here. Let's say someone sends you an email with hidden text that tells the agent to disregard its prior instructions.
The agent reads that message to write a reply, so it swallows the payload as a command.
A working injection could tell Claude to forward sensitive threads to an outside address or pull verification codes to break into other accounts.
Now, like Google, Anthropic also trains its models to flag malicious instructions and treat external content as untrusted input.
Still, security researchers consider prompt injection one of the hardest problems to close off completely. So maybe don't leave Claude in YOLO mode all the time.
My rule for what Claude gets to send without me
Some sending is low stakes and fine to automate. I put calendar replies, meeting confirmations, even some routine follow-ups in that bucket.
If an agent messes up a meeting status, you probably lose 15 minutes and some goodwill. If it touches money or feelings, I won't share every detail with the AI, and nothing leaves until I've read it.
The time you save by skipping a confirmation click is nothing compared to the time you spend apologizing for a hallucinated message.
This text was published by androidpolice.com and written by Ben Khalesi. It is reproduced here with attribution so you can read it in full; the rights remain with the publisher. Read it at the source ↗
The headline, key points and digest above were generated by Digest AI's editorial model from the linked sources. Automated summaries can contain errors: the sources are the record. Spotted a mistake? Tell us.
More in Agents & Tools
All →- NATO-backed Scaleout Systems adapts AI for autonomous drone recon and attack · 2 src
- Redditor creates free Veloop Chrome extension using Claude Code · 1 src
- meta platforms launches muse ai agent for mac · 15 src
- TypeSafe AI launches Jev decision‑making AI for routing customer inquiries · 2 src
- anthropic launches redesigned claude code projects with ai coordinator in beta · 6 src
Comments
via GitHub Discussions